Analysis conducted on 29 July 2026 indicates that the newly registered domain xbit-dex.com is being used in a generic phishing operation. The domain was created on 23 July 2026 and resolves to the IPv4 address 186.2.175.109. Registration records list Fewmoretaps OU d/b/a Trustname.com as the registrar, and the domain is served by four name servers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com.
The IP address is currently listed on a single public blocklist and has been added to the PhishDestroy blacklist, confirming that at least one threat‑intelligence feed has identified malicious activity associated with the host. VirusTotal has recorded 91 vendor scans; none of the scanners have raised a detection, but the absence of alerts does not constitute a safety guarantee. No additional public reputation services such as Google Safe Browsing or Open Threat Exchange are cited in the available intelligence, and no SSL certificate details or HTTP response codes have been disclosed.
The limited evidence points to an active phishing infrastructure that is still under investigation. Defenders should proactively block traffic to xbit-dex.com and its resolved IP address at the network perimeter, incorporate the domain and associated name servers into threat‑intelligence feeds, and continue to monitor the host for any changes in classification, additional blocklist listings, or emergence of malicious payloads. Ongoing collection of HTTP headers, page content, and any observed credential‑harvesting behavior will be essential for refining detection rules and completing the investigation.